Cyber Incident Victim: City of Potsdam
Date:
Apr 2023
Location:
Germany
Summary
A cyberattack, likely a distributed denial-of-service (DDoS) attack, disrupted the Brandenburg police website, making online services unavailable. The incident prompted an investigation by the state criminal investigation office on suspicion of computer sabotage. Technical countermeasures were implemented to mitigate the attack, and initial findings indicated no data breach had occurred. Similar attacks were also reported targeting the official state portal of Saxony-Anhalt, Mecklenburg-Vorpommern, and the Federal Development Ministry.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On April 4, 2023, a cyber incident caused significant disruptions to the official website of the Brandenburg police force. The issues began on the morning of Tuesday, April 4th, rendering online services unavailable to the public. A spokesperson for the Potsdam police headquarters, Beate Kardels, confirmed that the disruption was the result of a cyberattack. The initial assessment pointed to the attack being a Distributed Denial-of-Service (DDoS) incident, a method characterized by deliberately overwhelming a target's servers with a flood of internet traffic to render them inoperable. This type of attack aims to disrupt service availability rather than infiltrate systems to steal data.

The impact was immediate and public-facing. Visitors to the Brandenburg police website were met with a message stating, "Der Dienst ist vorübergehend abgeschaltet. Aufgrund von Wartungsarbeiten ist dieser Service aktuell nicht verfügbar. Wir sind in Kürze wieder für Sie da." This message, which translated to "The service is temporarily shut down. Due to maintenance work, this service is currently not available. We will be back for you shortly," indicated a temporary shutdown due to maintenance, though the underlying cause was the cyberattack. The specific online services that were incapacitated were not detailed, but the public's ability to interact with or receive services from the police website was completely halted. At the time of reporting, there was no clear timeline for when full functionality would be restored.
In response to the attack, technical teams implemented adjustments to the affected systems. These technical adaptations were designed to reduce the impact of the ongoing attack and mitigate its effects. The Brandenburg State Criminal Police Office (Landeskriminalamt) initiated a formal investigation into the incident based on the suspicion of computer sabotage. This investigation was tasked with determining the origin and full scope of the attack. According to the police spokesperson, based on the information available at the time, there was no indication that any data had been exfiltrated or compromised as a result of the attack. The primary consequence appeared to be service disruption.
This incident was not isolated to Brandenburg. The same article reported that the official state portal websites of Saxony-Anhalt were also paralyzed due to a similar DDoS cyberattack on the same day. Furthermore, there were additional reports of hacker attacks originating from Mecklenburg-Vorpommern and the Federal Ministry for Economic Cooperation and Development on that Tuesday. This suggests a broader pattern of coordinated or simultaneous attacks targeting German governmental and law enforcement online presence on April 4, 2023, though a direct connection between these separate events was not explicitly confirmed in the provided source material. The Brandenburg police incident was therefore part of a wider disruption affecting multiple German states and federal entities on that date. The investigation by the State Criminal Police Office remained ongoing to ascertain the full details and any potential links to these other events.
